An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
{ "cwe_ids": [] }
"https://github.com/psf/advisory-database/blob/main/advisories/python/PSF-2023-1.json"